Malware · 68 days ago
A package can look like a working payment SDK and still be a secret harvester. That is the break here: the fake client returns normal-looking results, which buys time to pull API keys and tokens from developer machines and CI runners before anyone notices the package is bogus.
Socket found 17 malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs. Multiple npm packages shipped malicious versions 1.0.0 through 1.0.3, and the payload stole developer credentials and exfiltrated them to AWS.
Removing the package does not undo the exposure. Any build or dev environment that installed one of these typosquats may already have leaked reusable secrets that can reach payment and cloud integrations downstream.
2 sources covering this story
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications.
Coordinated npm and PyPI Campaign Typosquats Popular Secure ...
Socket uncovered 17 malicious npm and PyPI packages typosquatting Paysafe, Skrill, and Neteller SDKs to steal developer secrets.
Part of the PlainSec briefing for 2026-07-08